plymouth-pretrigger.sh in dracut and udev, when running on Fedora 13...
Vulnerability Description
plymouth-pretrigger.sh in dracut and udev, when running on Fedora 13 and 14, sets weak permissions for the /dev/systty device file, which allows remote authenticated users to read terminal data from tty0 for local users.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2010-4176
Credits & Attribution
No credits recorded in the NVD database.
References
- http://www.securityfocus.com/bid/45046
- http://lists.fedoraproject.org/pipermail/package-announce/2010-December/051755.html
- http://secunia.com/advisories/42342
- http://secunia.com/advisories/42451
- http://lists.fedoraproject.org/pipermail/package-announce/2010-November/051418.html
- http://www.vupen.com/english/advisories/2010/3110
- https://bugzilla.redhat.com/show_bug.cgi?id=654489
- http://www.vupen.com/english/advisories/2010/3062
- https://bugzilla.redhat.com/show_bug.cgi?id=654935
Affected Vendor
dracut project
View all reports →Affected Software
Timeline
CVSS Vectors
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.